Skip to content

Conversation

@joycebrum
Copy link
Contributor

#197

Changes

Hash pin GitHub Owned Workflows: although they are more trustful than the overall github actions it is important to notice that they are still open source projects.

Let me know what you think.

PS: this is just an extra precaution, the workflow is already safe enough following minimal permissions on workflow. The hash pin will only ensure that no "malicious" version will be running instead of the original and trustful one.

joycebrum added 2 commits May 18, 2023 14:21
Signed-off-by: Joyce <joycebrum@google.com>
Signed-off-by: Joyce <joycebrum@google.com>
Copy link
Collaborator

@floitsch floitsch left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@floitsch floitsch merged commit 76ef844 into google:master May 20, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants